Kaspersky Warns Against AI-Generated Passwords on World Password Day

2 Sources

Share

Kaspersky's research reveals potential security risks in passwords generated by AI models, urging users to opt for dedicated password management tools instead.

News article

AI-Generated Passwords: A False Sense of Security

On World Password Day, cybersecurity firm Kaspersky has raised concerns about the growing trend of using AI-powered language models to generate passwords. While these AI-generated passwords may appear secure at first glance, they potentially harbor vulnerabilities that could compromise user security

1

.

The Allure of AI Password Generation

With the increasing number of online accounts requiring unique passwords, users are turning to AI for a quick solution. Large Language Models (LLMs) like ChatGPT, Llama, and DeepSeek offer an appealing alternative to the arduous task of creating strong, memorable passwords

2

.

Kaspersky's Research Findings

Alexey Antonov, Data Science Team Lead at Kaspersky, conducted a study generating 1,000 passwords using prominent LLMs. The research revealed several concerning patterns:

  1. Predictable character usage: ChatGPT, Llama, and DeepSeek showed preferences for specific characters, creating detectable patterns

    2

    .
  2. Dictionary word reliance: DeepSeek and Llama often generated passwords using modified dictionary words (e.g., "P@ssw0rd")

    2

    .
  3. Inconsistent adherence to security guidelines: 26-32% of passwords lacked special characters or digits, with some falling short of the recommended 12-character length

    2

    .

The Vulnerability of AI-Generated Passwords

Antonov's machine learning algorithm, designed to test password strength, yielded alarming results:

  • 88% of DeepSeek-generated passwords were vulnerable
  • 87% of Llama-generated passwords were susceptible to attacks
  • 33% of ChatGPT-generated passwords failed to meet security standards

    2

The Root of the Problem

The fundamental issue lies in the nature of LLMs. As Antonov explains, "LLMs don't create true randomness. Instead, they mimic patterns from existing data, making their outputs predictable to attackers who understand how these models work"

2

.

Recommendations for Secure Password Management

In light of these findings, Kaspersky advises against using AI for password generation. Instead, they recommend:

  1. Utilizing dedicated password management software, such as Kaspersky Password Manager
  2. Employing cryptographically secure generators for true randomness
  3. Storing credentials in a secure vault protected by a master password
  4. Taking advantage of features like auto-fill, cross-device synchronization, and breach monitoring

    2

The Importance of Robust Password Security

As data breaches become increasingly common, the need for strong, unique passwords for each account is paramount. While AI can assist with various tasks, password generation remains a critical security function best left to specialized tools designed explicitly for this purpose

2

.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo